Session

Expectation vs. Reality: Crushing user experience and productivity in the name of security

Cybersecurity is ultimately all about balancing risk management with productivity. Too often the mentality is: identify the bad thing, block the bad thing, tell the users to shun the bad thing, case closed, kingdom saved - right? Our experience says something is missing from that equation: the human factor and employee experience.

By treating business users like sheep, we are disregarding three of the most powerful drivers of security risks: frustration, creativity and most important: laziness. Whenever people encounter unexpected obstacles that they are motivated to overcome, we have an uncanny ability to find surprising ways to bypass them - unauthorized jury-rigged solutions which are often far worse for an organization's security posture than the original risk the technical controls were meant to protect from.

In this session, two seasoned security pros versed in psychology and equipped with deep practical experience unpack how and why idealistic and uncompromising security initiatives can (and often do) eventually backfire, manifesting as a silent and unmitigated workaround culture that breeds inefficiencies and discontent, raising new security risks and ultimately undermining the competitive edge of the business itself.

You will take home platform agnostic tips and tricks, along with a fresh outlook to help you properly use the licenses and tools you already have.

For example, you’ll be able to:
* Go from BlockPoint to SharePoint, opening up secure collaboration by using Microsoft Purview capabilities like DLP and Information Protection
* Avoid an exodus from Windows devices towards often looser-managed platforms like MacOS, driven by the desire for more user freedom
* Set up guardrails for handling business data on unmanaged devices with a thoughtful implementation of MAM
* Provide access to generative AI without compromising on essentials like audit logging and data security

The session is recommended for anyone looking for a fresh perspective on an important topic – especially security architects, technical experts and IT decision makers.

Tatu Seppälä

Blogger & speaker | Microsoft MVP | MCT | Data Security, Insider Risk, Power Platform Governance, IAM

Vantaa, Finland

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top